Common Weakness Enumeration is sustained by a community project with the goals of understanding flaws in software and creating automated tools that can be used to identify, fix, and prevent those flaws. The project is sponsored by the National Cybersecurity FFRDC, which is owned by The MITRE Corporation, with support from US-CERT and the National Cyber Security Division of the United States Department of Homeland Security.
CWE has over 800 Classifications, including classes for Buffer overflows, path/directory tree traversal errors, race conditions, Cross-site scripting, hard-coded passwords, and insecure random numbers.